Skip to content

Vulnerability Analysis and Reasoning Improvements - #132

Draft
ShadowBearVR wants to merge 15 commits into
chipsalliance:mainfrom
ShadowBearVR:vuln-improvements
Draft

ShadowBearVR wants to merge 15 commits into
chipsalliance:mainfrom
ShadowBearVR:vuln-improvements

Conversation

@ShadowBearVR

Copy link
Copy Markdown
Collaborator

No description provided.

@ShadowBearVR
ShadowBearVR force-pushed the vuln-improvements branch 8 times, most recently from c54ea8d to bf59bf2 Compare September 25, 2026 17:03
Add CWEValidator, search_cwe agent tool, and automated MITRE CWE
catalog synchronization script.
Add bundled MITRE CWE catalog (cwe_catalog.json) for offline validation
and agent keyword lookups.
Bypass redundant instruction state injection and recover from expired context
caches during long evaluations.
Add minPocSeverity threshold (default: Medium) to skip PoC synthesis
and secondary review passes on lower-severity findings.
Support passing exploit assertions and inline Rust harness tests
in the isolated worktree verification sandbox.
Avoid redundant reviewer agent invocations for findings that
have already completed an initial_review phase.
Add deterministic CVSS v3.1 base score calculator and structured
classification fields (cwe, attack_boundary, demonstrated_impact,
security_objective_violation) across finding models.
Require explicit 4-stage exploit path decomposition, CVSS v3.1 vector
calibration, and trust boundary / impact grounding in reviewer and
exploiter instructions.
Expose cwe, cvss_score, cvss_vector, attack_boundary, demonstrated_impact,
security_objective_violation, verdict, and history in WASM and render
them in the finding details modal.
Adds project configuration (project.nix), cross-compilation devShell
(shell.nix), Platform RoT threat model (threat_model.md), and wide-ranging
branch scan job (main.nix) for OpenPRoT.
Replaces hardcoded language-extension suffixes (TEST_FILE_SUFFIXES) and
directory lists (TEST_DIRECTORY_NAMES) with unified word-boundary token
matching (TEST_PATH_TOKENS) across directory segments and file stems.

This accurately identifies test and harness files across any language
(such as Rust src/tests.rs, *_tests.*, test_*, *.spec.*, and CamelCase
FooTest.* files) without false-matching substrings like 'attest.rs'.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant